CGAP Risk-Control Frameworks 3 ā Questions and Answers
Question 1: ISO 31000:2018 describes risk management as creating and protecting value. Which core principle most directly supports this by requiring risk management to be integrated into all organizational activities?
- Customized
- Inclusive
- Integrated (Correct answer)
- Dynamic
Correct answer: Integrated
ISO 31000 Principle 3 (Integrated) requires that risk management be part of all organizational activities, not a standalone function.
Question 2: In OMB Circular A-123, what is the primary purpose of management's assessment of internal control over financial reporting (ICFR)?
- To replace the external auditor's opinion on financial statements
- To provide reasonable assurance that financial reporting is reliable and assets are safeguarded (Correct answer)
- To eliminate the need for agency risk assessments
- To comply solely with FISMA cybersecurity requirements
Correct answer: To provide reasonable assurance that financial reporting is reliable and assets are safeguarded
OMB Circular A-123 requires agencies to assess ICFR to provide reasonable assurance of reliable financial reporting and proper stewardship of public assets.
Question 3: A CGAP candidate reviews a county's control environment. Which factor is LEAST indicative of a strong control environment?
- Tone at the top emphasizing ethical conduct
- A formal code of conduct with enforcement mechanisms
- Reliance on detective controls only, with no preventive controls (Correct answer)
- Clearly defined organizational structures and reporting lines
Correct answer: Reliance on detective controls only, with no preventive controls
Relying exclusively on detective controls without preventive controls indicates a weak control environment because problems are only caught after they occur.
Question 4: Which risk treatment option involves transferring risk exposure to a third party, such as through insurance or outsourcing?
- Risk avoidance
- Risk acceptance
- Risk sharing (Correct answer)
- Risk reduction
Correct answer: Risk sharing
Risk sharing (also called risk transfer) moves some or all of the financial impact of a risk to another party, such as an insurer or outsourced service provider.
Question 5: When applying the COSO Internal ControlāIntegrated Framework to a government entity, which component directly addresses the policies and procedures that help ensure management directives are carried out?
- Control Environment
- Risk Assessment
- Control Activities (Correct answer)
- Information and Communication
Correct answer: Control Activities
Control Activities are the specific policies and procedures (approvals, authorizations, reconciliations, etc.) that ensure management directives are executed and risks are mitigated.
Question 6: A federal agency's risk appetite statement says it will 'accept moderate financial risk to achieve mission-critical service delivery.' What does this imply for risk tolerance thresholds?
- All financial risks must be reduced to zero
- Specific risk tolerance bands should be set around the moderate risk level (Correct answer)
- Risk appetite and risk tolerance are identical concepts requiring no further specification
- External auditors must approve every risk tolerance threshold
Correct answer: Specific risk tolerance bands should be set around the moderate risk level
Risk appetite sets the broad direction, while risk tolerance defines the specific acceptable variation around that level; the agency should set quantitative thresholds reflecting 'moderate' financial risk.
Question 7: In the NIST Cybersecurity Framework (CSF), which function focuses on activities to identify the occurrence of a cybersecurity event?
- Identify
- Protect
- Detect (Correct answer)
- Respond
Correct answer: Detect
The Detect function encompasses activities to identify cybersecurity events in a timely manner, including continuous monitoring and anomaly detection.
ISO 31000:2018 describes risk management as creating and protecting value.
Which core principle most directly supports this by requiring risk management to be integrated into all organizational activities?